Privacy Policy
Last updated: 2026-09-05
Who we are
TELITASK LIMITED ("TeliTask", "we", "our", "us") is a private company registered in Kenya. We operate a voice-first AI platform at telitask.ai that makes and takes telephone calls on a business's behalf.
This notice is given under the Data Protection Act, No. 24 of 2019 of Kenya, which is the law that governs us. Section 29 of that Act requires us to tell you, before we collect your personal data, who is processing it and why. That is what this document is for.
If you do not agree with it, please stop using the service.
The two roles TeliTask plays
Which role we are in decides who is answerable to you, so it comes before everything else.
We are a data controller over the people who hold TeliTask accounts — our customers, their staff, their billing. We decide why and how that data is processed, and this notice describes it.
We are a data processor over the people our customers ask us to call. When a business uses TeliTask to phone its own customers, that business decides who is called and why; we act on its instructions. If you received a call from TeliTask on a business's behalf and want to know why you were called, or want your data deleted, the business that placed the call is the controller and is the right place to start. Contact us at privacy@telitask.ai and we will identify it for you and pass the request on.
Information we collect
Account information — name, email address, phone number, organisation name. Passwords are stored only as a salted hash; we never see the password itself.
Call data — the number dialled or calling, the date, time, duration and outcome of each call, and a written summary of what the call achieved.
Call content — a transcript of the conversation, and the facts the assistant learned during it (for example: a delivery was confirmed, an order was changed, a person asked to be called back). Where a business has asked us to keep a profile of the people it calls, those facts accumulate against that person's record so the next call does not start from nothing.
Call audio — see "Calls, recording and transcripts" below. Recording is currently switched off.
Payment information — payments are processed entirely by Paystack. We never receive or store your card number, expiry or CVV. We keep the transaction reference and billing history.
Technical information — IP address, browser type and version, operating system, timezone and language preference, and the error diagnostics described under Sentry below.
How we use your information
- To place and answer calls — the core of the service.
- To operate the assistant — understanding what was said, deciding what to say, and reporting the outcome back to the business.
- To bill you — subscriptions, invoices and account balance.
- To support you — answering your questions and fixing your problems.
- To keep the service working — diagnosing faults, monitoring quality, and fixing bugs.
We do not sell personal data. We do not use it for advertising. Call audio, transcripts and the facts learned on calls are not used to train any AI model — ours or a vendor's.
Where we rely on consent — marketing, and any call placed on the basis of consent — you can withdraw it at any time, and withdrawing it is as easy as giving it.
Calls, recording and transcripts
Call recording is switched off across the whole platform. No call audio is retained, for business calls or for the demo on our website. This is a platform-level setting (call_recording_enabled), and it fails safe: if the setting cannot be read, recording stays off.
If recording is ever switched back on, the assistant will say so at the start of the call, before the conversation begins, exactly as section 29 of the Act requires. Recording and the spoken notice are governed by the same switch and cannot be separated — there is no state in which we record without telling you.
A transcript of the conversation is produced whether or not audio is kept, because the assistant needs it to hold the conversation and to report the outcome. The transcript is text, not audio.
The assistant will never claim to be a person. If you ask whether you are speaking to an AI, it will tell you plainly that it is.
Who processes your data
We use the following providers. Each receives only what its function needs, and each is bound by its own processing terms.
| Provider | What it does | What it sees | | --- | --- | --- | | Supabase | Database, authentication and file storage | Account data, contacts, calls, transcripts | | Google (Gemini) | The model that conducts the conversation on the call | Live call audio and the transcript | | Cloud One | Telecommunications carrier — the calls themselves | Numbers dialled and call detail records | | LiveKit | Real-time media and SIP connectivity | Call audio while it is in transit | | Render | Hosting for the voice server | Everything the service holds in memory during a call | | Vercel | Hosting for the web dashboard | IP addresses and request metadata | | Upstash | Queue for scheduled calls | Queued call jobs, including phone numbers | | Sentry | Error monitoring | Whatever appears in an error report | | Resend | Transactional email | Email addresses and message content | | Cloudflare | Turnstile bot protection | IP addresses | | Paystack | Payments | Billing details | | Twilio | SMS phone-number verification, and WhatsApp replies where a customer has enabled them | Phone numbers and the message text | | xAI (Grok) | An alternative voice model, selectable per organisation and not used by default | Live call audio and the transcript, on calls where it is selected |
Twilio does not carry TeliTask's voice calls. Calls run over Cloud One as the carrier, with LiveKit and FreePBX handling media and routing. Twilio is used only for the SMS and WhatsApp purposes named above.
We update this table when the stack changes. If you find it out of date, tell us at privacy@telitask.ai — an inaccurate list is a problem in itself.
Data retention
- Call audio — none is kept, because recording is off. If it is switched back on, audio is deleted after 30 days.
- Transcripts and call outcomes — kept while the business customer's account is active, and deleted with it.
- Facts learned about a person a business calls — kept only while they are still useful to that business, and deleted when the business's account closes or when the business asks us to delete them, whichever is first.
- Account data — kept while the account is active. On a deletion request we remove it within 30 days.
- Billing records — kept for as long as Kenyan tax and company law requires, currently seven years.
- Error diagnostics — kept for 90 days.
The Act requires that personal data is kept no longer than the purpose needs. If you think we are holding something longer than we should, say so and we will look at it.
Your rights under the Data Protection Act 2019
Under Part V of the Act you have the right to:
- Be informed of the use to which your personal data is put (section 26(a)).
- Access the personal data we hold about you (section 26(b)).
- Object to the processing of all or part of your personal data (section 26(c)).
- Correct false or misleading data (section 26(d)).
- Delete false or misleading data about you (section 26(e)).
- Data portability — receive your data in a structured, commonly used format, where section 38 applies.
- Not be subject to a decision based solely on automated processing that significantly affects you, without human review.
To exercise any of these, email privacy@telitask.ai. We will respond within 30 days. We do not charge for this, and we will not treat you differently for asking.
If you were called by TeliTask on a business's behalf, see "The two roles TeliTask plays" above — we will route your request to the business that instructed the call and help you get an answer.
If the GDPR or CCPA also applies to you
Kenyan law governs this notice. If you are in the European Economic Area or in California, the rights listed above are broadly equivalent to those under the General Data Protection Regulation and the California Consumer Privacy Act, and we will honour a request made under either on the same basis and in the same timeframe. We do not sell personal information as the CCPA defines it.
Marketing communications
With your explicit consent we may send product updates and offers by email, SMS, WhatsApp or Telegram. Under section 37 of the Act, using personal data for commercial purposes requires express consent — a past interaction, a purchased list or a scraped number is not consent, and we do not treat it as one.
You can withdraw consent at any time by:
- Turning the channel off in Settings → Notifications
- Clicking "Unsubscribe" in any marketing email
- Replying STOP to any marketing SMS or WhatsApp message
- Sending /unsubscribe to our Telegram bot
We keep an audit log of consent changes, which is itself a record we are required to be able to produce.
Cookies
We use a minimal set of strictly necessary cookies: an authentication session, your language preference and your light or dark theme choice. We use no advertising cookies, no third-party tracking cookies and no cross-site analytics. This is why you are not asked to dismiss a cookie banner.
Transfers outside Kenya
Some of the providers above operate outside Kenya. Supabase hosts our database in the United States (us-east-1 and us-east-2), and Google processes call audio outside Kenya.
Sections 48 and 49 of the Act govern these transfers. The Data Commissioner has issued no adequacy decisions, so we do not rely on one. We rely instead on the contractual safeguards in each provider's data processing terms, together with a documented assessment that the transfer is necessary for the performance of the service you asked for. We can produce that record on request.
Security
Access to customer data is separated by organisation at the database level, so one customer's account cannot read another's. Credentials that bypass those controls are held only on our servers and never reach a browser. Traffic to the dashboard and between our services is encrypted in transit.
Section 43 of the Act requires us to notify the Data Commissioner within 72 hours of becoming aware of a breach that poses a real risk of harm, and to notify affected people. Where we are acting as a processor for a business customer, we will notify that customer within 48 hours.
No system is perfectly secure, and we will not tell you otherwise. If you believe you have found a vulnerability, email privacy@telitask.ai.
Children's privacy
TeliTask is not intended for anyone under 18, and section 33 of the Act requires consent from a parent or guardian before a child's data is processed. We do not knowingly collect data from children. If we learn that we hold a child's data without that consent, we delete it. If you believe we hold your child's data, contact us.
Changes to this policy
We update this notice when the product or the stack changes, not on a schedule. When a change is material we email account holders at the address on the account, and the revised date at the top of this page changes.
Contact us and how to complain
Email: privacy@telitask.ai Website: telitask.ai Entity: TELITASK LIMITED, a private company registered in Kenya
If you are not satisfied with how we have handled your data or your request, you have the right to complain to the Office of the Data Protection Commissioner (ODPC) of Kenya, which can investigate and order us to act:
ODPC — odpc.go.ke · info@odpc.go.ke
You do not have to come to us first, though we would rather you did.